-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hello all,
I have been testing OSSEC active response recently and my results indicate that using the 'all' location in an active response rule worked fine in v 1.4, but works as 'local' in 1.5 (ie, it only works on the machine that generated the alert and not across all machines). Any thoughts on this? I'm very curious to see if this is a bug or a misconfiguration on my part (although I have double-checked that my rules and commands do not have errors, and they work perfectly using defined-agent and server). Thanks for your time, - -- Nikita Byalsky Information Security and Unix Systems University of Pennsylvania School of Arts and Sciences 3600 Market St., Suite 501 Philadelphia, PA 19104 215.573.8772 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (GNU/Linux) Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org iD8DBQFIWQoibHfl5jKHKasRAhAvAJ9CAb9w72vc6gDUIl6vpUhPbQNYRwCfSwCf oh/8Df8P30yMtrIs1c2xp2s= =uNAZ -----END PGP SIGNATURE-----
